Running a Better Business

What Cybersecurity Controls Does a Small Business Need First?

You do not need enterprise security; you need the baseline that defeats the automated, opportunistic attacks behind most small-business incidents. Canada's Cyber Centre has published exactly that list.

Numera Decision LibraryGrounded in official sourcesEducational publication
Why this decision matters

Most successful attacks on small businesses are not targeted; they are harvested — a phished password, an unpatched system, a login with no second factor, found by automated scanning at scale. The encouraging corollary: a modest baseline of controls removes you from the harvest.

The Canadian Centre for Cyber Security publishes baseline controls specifically for small and medium organizations. The list below follows that philosophy, ordered by impact.

The central idea

Multi-factor authentication, tested backups, and prompt patching defeat the majority of real-world attacks on small firms.

The first tier is non-negotiable. Multi-factor authentication on email, banking, accounting, and remote access — email above all, because a compromised inbox is the master key to password resets and payment fraud. Backups that are automatic, kept offline or immutable where ransomware cannot reach them, and actually tested by restoring — an untested backup is a hope, not a control. Updates applied promptly to operating systems, browsers, and applications, with auto-update on wherever possible.

The second tier hardens the human and administrative layers: a password manager enabling unique passwords everywhere; administrator rights removed from daily-use accounts; staff trained — briefly, regularly — to recognize phishing and to verify payment instructions by phone; offboarding that revokes access the day someone leaves; and a one-page incident plan naming who to call — your IT support, your bank, the Cyber Centre, your insurer — before the bad day arrives. Cyber insurance, increasingly, both backstops and enforces this baseline.

What changes the answer

Factors that matter

  • Email as the crown jewelNearly every business compromise begins in the inbox — secure it first and hardest.
  • Ransomware resilienceOffline or immutable backups convert ransomware from an existential threat into a bad week.
  • Cloud responsibilitiesCloud tools shift some burden to vendors, but access control and configuration remain yours.
  • Vendor and payment processesCyber controls and fraud controls converge at payment verification — one procedure serves both.
  • Insurance requirementsCyber policies increasingly mandate MFA and backups; the application form is a useful self-audit.
Decision framework

Before you decide

  • Is MFA enforced on email, banking, accounting, and remote access — for everyone?
  • When did we last restore a file from backup to prove it works?
  • How quickly are updates applied, and is anything running unsupported software?
  • Do daily-use accounts carry administrator rights they do not need?
  • Who does each employee call, first, when something looks wrong?
Practical next steps

Move from question to action.

01

Turn on MFA everywhere this week, starting with email.

02

Implement automatic backups with an offline or immutable copy, and calendar a quarterly restore test.

03

Enable automatic updates; inventory and retire unsupported systems.

04

Deploy a password manager and strip admin rights from daily accounts.

05

Run brief phishing awareness sessions twice a year and write the one-page incident plan.

Educational use notice

This publication is part of the Numera Decision Library and is provided for education only. It is general information — not accounting, tax, legal, or investment advice — and it does not consider your personal circumstances. Every guide is grounded in official guidance from government and regulated authorities — including the Canada Revenue Agency (CRA), the Department of Finance Canada, Service Canada and Employment and Social Development Canada, the Internal Revenue Service (IRS), and the Canadian Centre for Cyber Security — with the sources listed at the end of each guide. Tax rules and dollar limits change; confirm current figures with the official source, and speak with a qualified professional before acting on any decision discussed here.

Official references

Sources are official government and regulated-authority publications. Official sites reorganize periodically — search the document title if a link has moved.

NUMERA
Accounting Advisory

Clarity. Strategy. Impact.

The Numera Decision Library exists because informed owners make better decisions. Every guide is grounded in official government sources, written in plain language, and designed to prepare you for the conversation that matters — the one with your own advisor.

www.numeraaccounting.online